shopify-expert

Fail

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Detailed guidance in references/performance-optimization.md includes a code example that dynamically loads and executes a script from https://third-party.com/widget.js. This domain is flagged by security scanners as associated with botnet activity.
  • [METADATA_POISONING]: The author field in the SKILL.md frontmatter identifies the developer as https://github.com/Jeffallan, which conflicts with the expected author context of 1git2clone.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted configuration files and e-commerce data, creating a potential attack surface.
  • Ingestion points: Shopify theme files (.liquid), app configuration (shopify.app.toml), and GraphQL schemas processed via Shopify CLI.
  • Boundary markers: Absent. The skill lacks specific instructions to delimit or ignore instructions embedded in the Shopify data it processes.
  • Capability inventory: The skill utilizes the Shopify CLI and Admin/Storefront APIs to perform file system writes and network operations.
  • Sanitization: No explicit logic is provided to sanitize input from external templates or schemas before processing.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — shopify-expert